Troj/Agent-KIR is a Trojan for the Windows platform.
When run Troj/Agent-KIR creates the files:
<Temp>\bassmod.dll - can be safely deleted
<Temp>\keygen.exe - detected as Troj/Agent-KIR
<Temp>\nzm.exe - detected as Troj/Agent-KIR
<System>\winupdate.exe - detected as Troj/Agent-KIR
The following registry entries are set:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Updater
winupdate.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Updater
winupdate.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Updater
winupdate.exe
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
|
|:*:Enabled:Microsoft Updater